QR Code Phishing at Work★ How to Check QR Codes in Emails, PDFs, and Posters

 

QR Code Phishing at Work★

How to Check QR Codes in Emails, PDFs, and Posters

QR codes are everywhere now.

You see them in emails, PDF files, posters, invoices, event signs, parking notices, delivery messages, and office documents.

That convenience is exactly why attackers use them.

A QR code can hide the real link until after you scan it.
That makes it harder to judge quickly, especially when the QR code appears inside a work email or document.

This type of scam is often called QR code phishing or quishing.

The message might say:

“Scan to open the secure document.”
“Scan to view your Microsoft 365 file.”
“Scan to confirm the invoice.”
“Scan to update your account.”
“Scan to review the HR form.”

The QR code may look harmless, but it can send you to a fake login page, a payment scam, or a malicious website.

Before scanning, slow down.

The goal is simple:

Do not scan first and verify later. Check the context, link preview, and destination before you enter any information.



1. Why QR code phishing works

QR code phishing works because it moves the risk from your computer to your phone.

A suspicious link in an email may be blocked or previewed by your email system.

But a QR code is just an image.

When you scan it with your phone, you may leave the protected work environment and open the link on a personal device.

That can make the scam harder to notice.

A QR code can appear in:

  • Outlook emails

  • PDF attachments

  • shared documents

  • invoices

  • posters in public places

  • meeting room signs

  • parking payment signs

  • delivery notices

  • event registration pages

This does not mean every QR code is dangerous.

It means you should treat unexpected QR codes like unexpected links.

2. Check where the QR code came from

Before scanning, ask one basic question:

Was I expecting this QR code?

Be careful if the QR code came from:

  • an unexpected email

  • a PDF attachment you did not request

  • a message from an unknown sender

  • a poster with no clear organization name

  • a payment notice placed in a public area

  • a document that creates urgency

  • a message asking you to sign in again

For work, the safest habit is to verify the source first.

If the QR code claims to open a Microsoft 365, Google Workspace, Dropbox, or payment page, do not scan it just because the design looks official.

Check the sender, document context, and official app first.

3. Preview the link before opening it

Many phones show a link preview after you scan a QR code.

Do not tap the link immediately.

Look at the domain first.

Be careful with:

  • misspelled domains

  • random short links

  • unfamiliar login pages

  • long confusing URLs

  • domains that do not match the company

  • pages asking for your password

  • pages asking for payment or personal data

For example, if a QR code claims to open a Microsoft 365 document, the destination should make sense.

If the preview shows a strange domain, stop.

A simple rule:

If the QR code destination does not match the message, do not open it.


4. Be extra careful with QR codes in PDFs

QR codes inside PDFs can look very professional.

That is why they are common in workplace scams.

A fake PDF might look like:

  • an invoice

  • a secure document notice

  • a voicemail message

  • an HR form

  • a shared file alert

  • a shipping document

  • a meeting note

  • a payment confirmation

The PDF may say you need to scan the QR code to continue.

That is a red flag.

Before scanning a QR code in a PDF, ask:

  • Was I expecting this document?

  • Do I know the sender?

  • Is the file name specific or vague?

  • Can I access the file directly from the official app?

  • Why does this PDF need a QR code instead of a normal link?

  • Is it asking me to sign in or pay?

If the PDF is unexpected, verify with the sender through another channel.

Do not reply directly to the suspicious email.

5. Be careful with QR codes on posters and public signs

QR code phishing is not limited to email.

Attackers can place fake QR codes on physical posters, flyers, payment signs, parking meters, or package notices.

This can be risky because a physical QR code may look trusted just because it is printed in a real location.

Before scanning a public QR code, check:

  • Is the sign professionally printed or cheaply added?

  • Does the QR code look like a sticker placed over another code?

  • Is the organization name clear?

  • Is there an official website you can type manually instead?

  • Does the page ask for payment or login details?

  • Does the URL match the organization?

For parking, ticketing, delivery, or payment situations, it is often safer to open the official app or website directly.

6. What to do after scanning a suspicious QR code

If you scanned a suspicious QR code, do not panic.

What matters is what you did next.

If you only scanned it and closed the preview without opening the link, the risk is usually lower.

If you opened the page but did not enter anything, close it and report the message if it came from work email.

If you entered a password, payment information, or MFA approval, act quickly.

Do this:

  1. Close the page

  2. Do not enter more information

  3. Change your password from the official site

  4. Report it to IT or your security team

  5. Check recent account activity if available

  6. Contact your bank or payment provider if payment details were entered

  7. Keep the email, PDF, or photo of the QR code for review

For work accounts, report it even if nothing looks wrong yet.

7. Quick checklist before scanning a QR code


Before scanning a QR code in an email, PDF, poster, or work message, check this list:

1. Source
Do I know where this QR code came from?

2. Context
Was I expecting this document, payment, file, or request?

3. Link preview
Does the destination domain look correct?

4. Urgency
Is the message pressuring me to act quickly?

5. Login request
Is it asking me to sign in again?

6. Payment request
Is it asking for money, card details, or account information?

7. Official app check
Can I access the same thing from the official app or website?

8. Verification
Can I confirm it with the sender, IT, or the organization directly?

If two or more answers feel suspicious, do not scan or continue.

Final thoughts: treat QR codes like hidden links

A QR code is just another way to open a link.

The problem is that you cannot easily see the full destination before scanning.

That is why QR code phishing works.

The safest habit is simple:

Preview the destination, verify the source, and never enter login or payment information from an unexpected QR code.

For work, be especially careful with QR codes in emails, PDFs, shared documents, and posters.

When in doubt, open the official app or website directly instead of using the QR code.

신고하기

이 블로그 검색

오른쪽박스

왼쪽 광고